AI Is Speeding Up Cyberattacks, Not Reinventing Them

Sophos’ new AI Security 2026 report, drawn from casework across more than 625,000 customer organisations, delivers a clear message: artificial intelligence isn’t creating new kinds of cyberattacks — it’s making old ones faster. Attackers still need to break in, move around, and steal data. What’s changed, the report argues, is the clock.

A Real-World Wake-Up Call

The report opens with a striking case: in May 2026, Sophos discovered an attacker running roughly a dozen AI agents inside a customer’s network, each testing malware against different security tools on its own virtual machine. Coordinated through a coding assistant, the agents produced nearly 80 malware modules and over 70 evasion techniques — work that would normally take a human developer weeks, compressed into days. The operator later used this toolkit to deploy ransomware and steal data.

Criminals Are Adopting AI Like Any Other Tool

Sophos found threat actors buying and selling AI API access on underground forums, recruiting “AI prompt engineers,” and advertising AI-powered voice bots and fake romance-fraud personas. But adoption isn’t universal — some criminals remain sceptical AI will change their business at all. The pattern looks less like a revolution and more like criminals slowly folding a new tool into old habits.

Enterprises Have a Blind Spot

A major theme is how AI tools themselves have become targets. Incidents like the Salesloft/Drift breach and a Vercel hack (triggered by an employee’s AI tool) show how stolen credentials and OAuth tokens tied to AI assistants can open the door to company systems. Alarmingly, the report cites survey data showing that 71% of large enterprises have deployed AI agents with access to core business systems, but only 16% properly govern that access.

Defenders Are Using AI Too — With Limits

On the positive side, AI reasoning models are helping security teams investigate alerts faster, cutting hours of analyst work into minutes. But Sophos cautions this isn’t magic: current AI tools lack memory between sessions, meaning they investigate every alert as if for the first time, and over-relying on “reasoning” can sometimes make results worse rather than better.

What Companies Should Do Now

The report closes with practical advice: build visibility into which AI tools and agents have access to company data, tighten identity and credential controls around them, and patch known vulnerabilities faster — since AI is shrinking the gap between a flaw being disclosed and being exploited, sometimes to under 24 hours. For companies deploying their own AI agents, Sophos recommends sandboxing, credential isolation, and human approval for any irreversible actions.

The bottom line: AI hasn’t rewritten the rules of cybersecurity yet — but it has sped up the game on both sides, and organisations that don’t adjust their own tempo risk falling behind.

Author